Notifications
Clear all

DECAF

10 Posts
8 Users
0 Reactions
1,561 Views
(@keeper)
Estimable Member
Joined: 17 years ago
Posts: 106
Topic starter  

New app surfaced into the web, capable of counter acting Microsoft COFEE. The tool must be running, and if it detects the precense of M$ COFEE, it can perform several pre-configured anti-forensics routines.

Features
* Contaminate MAC Addresses Spoof MAC addresses of network adapters
* Kill Processes Quick shutdown of running processes
* Shutdown Computer On the fly machine power down
* Disable network adapters
* Disable USB ports
* Disable Floppy drive
* Disable CD-ROM
* Disable Serial/Printer Ports
* Erase Data Quick file/folder removal (Basic Windows delete)
* Clear Event Viewer Remove logs from the Event Viewer
* Remove Torrent Clients Removes Azureus and BitTorrent clients
* Clear Cache Remove cookies, cache, and history

It's freeware, and it can be downloaded from the homepage DECAF


   
Quote
(@unknown)
Eminent Member
Joined: 17 years ago
Posts: 21
 

The restrictions are ironic

Restrictions
The source code, design, and structure of DECAF are trade secrets. You will not disassemble, decompile, or reverse engineer it, in whole or in part, except to the extent expressly permitted by law. You will not use DECAF for illegal purposes. You will comply with all export laws. DECAF is licensed, not sold.
lol


   
ReplyQuote
(@securit)
Active Member
Joined: 20 years ago
Posts: 10
 

You have to ask, what is this software doing that you don't know about? Until it is reverse engineered then no one will know will they….although plenty of people will be using it I imagine -)


   
ReplyQuote
(@jelle)
Trusted Member
Joined: 18 years ago
Posts: 52
 

You have to ask, what is this software doing that you don't know about?

It's not doing a lot anymore 😉

We want to thank every media outlet, financial supporter, security expert, and forensic investigator that showed us support.

As you probably noticed, your copy of DECAF no longer works. We have self destructed every copy of DECAF. We hope that as you realize this was a publicity stunt to raise awareness for security and the need for better forensic tools that you would reconsider cutting corners on corporate security. Also, our government should not rely on a tool to automate the process of forensics but rather invest in the education of investigators and forensic tool experts.

See the site.


   
ReplyQuote
(@jonathan)
Prominent Member
Joined: 20 years ago
Posts: 878
 

See the site.

Really quite odd. So it was all a hoax perpetrated by a Christian fundamentalist?


   
ReplyQuote
Wardy
(@wardy)
Estimable Member
Joined: 20 years ago
Posts: 149
 

I think there were several points made, not just the religious aspect. Still strange though.


   
ReplyQuote
(@llista)
Active Member
Joined: 18 years ago
Posts: 17
 

Apparently DECAF calls home first before is allowed to work. That is how they disabled it.

There is a work around to activate it again, I am not sure if I am allowed to post the link.

Google "Reactivating DECAF in Two Minutes" and the praetorianprefect blog should come up.


   
ReplyQuote
(@keeper)
Estimable Member
Joined: 17 years ago
Posts: 106
Topic starter  

Simply use your firewall to block outbound access for the app.

Update If you do that, the app will crash.


   
ReplyQuote
(@torqueman)
New Member
Joined: 15 years ago
Posts: 2
 

There is all ready a working version out there that has the phone home feature removed.


   
ReplyQuote
(@keeper)
Estimable Member
Joined: 17 years ago
Posts: 106
Topic starter  

v2.0.1 works perfectly. (no home-calling feature or alike)


   
ReplyQuote
Share: